Why $20 Hotspots Beat $300 SDRs

▶ Watch (11:29)

Crocodile Hunter, the first attempt, required a $300 software-defined radio, a Linux laptop, and antennas. The output was a map full of false positives. Journalists and activists could not set it up or interpret results. Ray Hunter runs on a $20 Qualcomm-based hotspot, installs easily, and presents a simple web UI. Users carry it like a normal device. It records PCAPs and runs heuristics automatically. No compilation, no antennas, no $300 SDR.

The Pre-Authentication Weak Spot in 4G LTE

▶ Watch (7:15)

2G required the phone to authenticate but not the tower. 4G reversed that, but dozens of messages are exchanged before authentication ever happens. The RRC and NAS layers carry system information blocks, identity requests, and attach requests without proof the tower is legitimate. This is where modern cell-site simulators operate. Even 5G does not fix it—attackers can jam 5G and force a downgrade to 4G. Group 2000 sells a product that lets cops turn off 5G in a geofenced area with a button.

Four Heuristics for Detection

▶ Watch (19:13)

The phone network is messy. Legitimate towers sometimes ask for IMSI, drop connections, or use null ciphers. Ray Hunter uses four heuristics to separate signal from noise. Incomplete SIB chains: real towers send 5–7 system information blocks; fake base stations often send only 1, 2, and 3. The wallet inspector attack: an identity request followed by a disconnect without authentication. 2G downgrade and null cipher complete the set. Each heuristic can be tuned per region—downgrade warnings make sense in the US where 2G is dead, but not elsewhere.

Real-World Field Results

▶ Watch (25:09)

A user named Zero Chaos ran Ray Hunter on a Caribbean cruise. Near Turks and Caicos, the tool logged a null cipher request every three seconds for an hour, plus malformed SIBs and identity requests. Cooper called it the most suspicious tower he had ever seen. In downtown Chicago, a user got dozens of identity requests without authentication over one hour. Chicago PD and ICE both own cell-site simulators. At Penn Station in New York, another user recorded similar activity for an hour; two days later nothing appeared. Protests from the summer of 2025 showed no detections.

Porting Ray Hunter to More Devices

▶ Watch (32:02)

Any device with a Qualcomm modem that exposes DIAG messages can run Ray Hunter. The team wants community ports for ITU Region 3 (Asia-Pacific). Porting requires rooting the device, building the Rust binary, verifying LTE messages appear, and adding a display method (screen, LEDs). The project now compiles with a pure Rust toolchain—no GCC needed. Contributors only need rustup installed. The installer is a Rust binary that handles ADB, Telnet, and device detection cleanly. Over a dozen devices are already supported.

Notable Quotes

“they had seen some signs of what they thought were MC catchers and sent them to us” Cooper Quintin · ▶ 2:33

“I actually accused him of setting this up to be a a test of Ray Hunter because it was so damn suspicious” Cooper Quintin · ▶ 26:22

“if you want to run a fake Stingray at home, please don’t. You’ll make the FCC very mad.” Cooper Quintin · ▶ 29:56

“Dad, yeah, why don’t you just tell those hackers to turn off their phones?” Cooper Quintin’s son River · ▶ 38:03

Key Takeaways

  • Ray Hunter turns $20 mobile hotspots into cell-site simulator detectors.
  • Detection relies on four heuristics that exploit pre-authentication LTE messages.
  • Field tests flagged real suspicious activity in Chicago, Penn Station, and Turks and Caicos.

About the Speaker(s)

Cooper Quintin is a senior public interest technologist with the EFF Threat Lab. He has given talks about security research at Black Hat, DEFCON, Shmoocon, and ReCon on topics from IMSI catcher detection to APT analysis.

oopsbagel is an open source contributor, wireshark user, and hardware hacker who loves breaking Kubernetes and floaking.